← 返回 Skills 市场
membranedev

Smarty

作者 Membrane Dev · GitHub ↗ · v1.0.3 · MIT-0
cross-platform ⚠ suspicious
156
总下载
0
收藏
0
当前安装
4
版本数
在 OpenClaw 中安装
/install smarty
功能描述
Smarty integration. Manage Organizations, Pipelines, Users, Goals, Filters. Use when the user wants to interact with Smarty data.
安全使用建议
This skill's runtime instructions (use the Membrane CLI) look normal, but the metadata and SKILL.md contradict each other about what 'Smarty' refers to. Before installing: 1) Confirm with the publisher which 'Smarty' this skill integrates with (PHP template engine vs. address/data connector). 2) Verify the publisher and repository (the SKILL.md points to Membrane; check that @membranehq on npm and the repository are legitimate). 3) Prefer testing the npm CLI in a sandbox or container rather than doing a global npm install on a production machine. 4) Be aware the workflow uses browser-based auth and Membrane servers (network access) which will grant the Membrane service access to the connected external accounts; verify privacy/permissions for those connections. The static scanner had no code to analyze (instruction-only), so absence of findings does not guarantee safety.
功能分析
Type: OpenClaw Skill Name: smarty Version: 1.0.3 The skill bundle exhibits high-risk behavior by instructing the agent to perform global system modifications (npm install -g) and execute shell commands for authentication and remote action execution. The documentation in SKILL.md is highly inconsistent and misleading, conflating the Smarty PHP template engine with Smarty (formerly SmartyStreets) address verification services and CRM-like features (Pipelines/Goals). While these commands are part of the legitimate Membrane platform (getmembrane.com) workflow, the requirement for global NPM installs and the confusing instructions pose a security risk and suggest poor quality control or automated generation without verification.
能力评估
Purpose & Capability
The registry description says: 'Manage Organizations, Pipelines, Users, Goals, Filters.' The SKILL.md, however, describes Smarty as a PHP template engine and then documents using the Membrane CLI to run address/data verification actions (international-address-autocomplete, verify-us-address, etc.). It's unclear whether this skill targets the Smarty template engine, the Smarty/SmartyStreets data connector, or is simply misnamed. This mismatch is not explained by the metadata.
Instruction Scope
The SKILL.md is instruction-only and tells the agent to install and run the Membrane CLI, create connections, list actions, and run actions. Those steps stay within the stated runtime model (Membrane CLI + network + browser auth). The instructions do require network access and interactive/browser-based authentication, but they do not instruct the agent to read arbitrary local files or to exfiltrate secrets. There is some vagueness around agentType values and expected interactive steps that could affect automation.
Install Mechanism
There is no registry install spec, but SKILL.md asks the user to run 'npm install -g @membranehq/cli@latest' (a global npm install). Installing a CLI from an npm scope is reasonable for a CLI-based integration, but global npm installs are privileged on the host and should be from a trusted publisher. No downloads from arbitrary URLs or archive extraction are requested.
Credentials
The skill declares no required env vars or credentials and instructs that Membrane handles authentication via browser/CLI flow. It explicitly advises not to ask the user for API keys. The credential requirements appear proportionate to the described Membrane-CLI workflow.
Persistence & Privilege
The skill is not forced-always (always:false) and allows normal autonomous invocation (default). It does not request system-wide config paths or other skills' credentials. No additional persistence or special privileges are requested in the instructions.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install smarty
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /smarty 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.3
Auto sync from membranedev/application-skills
v1.0.2
Revert refresh marker
v1.0.1
Refresh update marker
v1.0.0
Auto sync from membranedev/application-skills
元数据
Slug smarty
版本 1.0.3
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 4
常见问题

Smarty 是什么?

Smarty integration. Manage Organizations, Pipelines, Users, Goals, Filters. Use when the user wants to interact with Smarty data. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 156 次。

如何安装 Smarty?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install smarty」即可一键安装,无需额外配置。

Smarty 是免费的吗?

是的,Smarty 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Smarty 支持哪些平台?

Smarty 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Smarty?

由 Membrane Dev(@membranedev)开发并维护,当前版本 v1.0.3。

💬 留言讨论